How DFARS Compliance and CMMC Work Together

How DFARS Compliance and CMMC Work Together

Key Takeaways

  • DFARS 252.204-7012 requires any defense contractor handling controlled unclassified information (CUI) to implement the 110 security controls in NIST SP 800-171 and report any cyber incident affecting CUI to the DoW within 72 hours of discovery.
  • CMMC 2.0 does not replace DFARS. It operationalizes DFARS by adding a formal assessment and certification structure on top of NIST SP 800-171 controls.
  • The 32 CFR CMMC Program Rule took effect in December 2024 and the 48 CFR acquisition rule that lets contracting officers put CMMC into contracts took effect November 10, 2025.
  • CMMC is rolling out in four phases through November 2028 and Phase 2, which brings mandatory third-party Level 2 certification, begins November 10, 2026.
  • Contractors must post an accurate NIST SP 800-171 score in the Supplier Performance Risk System (SPRS), a requirement now folded into DFARS 252.204-7021 after a February 2026 regulatory overhaul and a false affirmation can create False Claims Act liability.
  • Getting ahead of CMMC Level 2 certification now, rather than waiting for a solicitation deadline, is the only way to avoid getting locked out of upcoming DoW awards.

Note: As of July 13, 2026, the Department of War suspended CMMC Phase 2, along with Phases 3 and 4, pending a 60-day program review, so the November 10, 2026 dates referenced below are no longer active deadlines. Phase 1 self-assessment requirements, DFARS 252.204-7012, and annual SPRS affirmations remain fully in effect, and this is a policy pause rather than a repeal: the underlying CMMC Program rule and DFARS clauses are unchanged. Contractors already working toward Level 2 certification should keep going – a reformed requirement, and a resumed timeline, could return once the review concludes. We will update this article with accurate timelines once the review has been completed.

A single contract clause has quietly reshaped how thousands of companies think about cybersecurity. Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 has required defense contractors to protect CUI for years, but self-attestation gave the government little confidence that contractors were doing what they claimed. Cybersecurity Maturity Model Certification (CMMC) changed that by adding independent verification to a requirement that already existed within the government contracting model.

For IT managers and compliance leads across the Defense Industrial Base (DIB), the two frameworks can feel like separate mandates layered on top of each other, but they are not. DFARS sets the contractual obligation and CMMC gives the Department of War (DoW) a way to confirm contractors are meeting it. Understanding how they fit together is the first step toward building a compliance program that satisfies both.

This article walks through what DFARS and CMMC require, how they map to one another, where the rollout stands today and what your organization needs to do right now to stay eligible for DoW work.

What Does DFARS 252.204-7012 Require?

DFARS is the DoW’s supplement to the Federal Acquisition Regulation (FAR), which defines procurement across federal agencies. Within DFARS, clause 252.204-7012 is the provision that matters most for cybersecurity.

DFARS 252.204-7012 applies to any contractor or subcontractor that processes or stores covered defense information, most commonly CUI. First, contractors must implement the 110 security controls specified in NIST SP 800-171. Second, contractors must report any cyber incident affecting covered information to the DoW within 72 hours of discovery.

DFARS 7012 has been in contracts since 2017, but enforcement historically relied on self-attestation. A contractor signed a statement saying they met the requirements, and the government generally took that statement at face value unless an audit or breach proved otherwise.

That gap between what contractors claimed and what they had implemented is exactly the problem CMMC was designed to close and it’s also why so many contractors lean on managed IT services built for government contractors to keep DFARS 7012 controls running day to day rather than treating them as a one-time checklist.

What Is CMMC 2.0 and How Does It Build on DFARS?

CMMC is the DoW’s framework for verifying that contractors meet the cybersecurity controls that DFARS 7012 requires. CMMC 2.0 organizes contractors into three tiers based on the sensitivity of the information they handle.

  • Level 1 applies to contractors handling only Federal Contract Information (FCI) and requires an annual self-assessment against 17 basic practices.
  • Level 2 applies to contractors handling CUI and is built directly on the same 110 NIST SP 800-171 controls that DFARS 7012 already mandates.
  • Level 3 adds a further 24 controls from NIST SP 800-172 for the highest priority programs and requires assessment by the DoW’s own Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

Verification is the critical difference between CMMC and the DFARS 7012 self-attestation model. Most Level 2 contractors will need an assessment from a Certified Third-Party Assessment Organization (C3PAO), an accredited independent auditor who reviews evidence and confirms the controls are in place and working. Some Level 2 contracts still allow self-assessment, but the DoW retains discretion to require full C3PAO certification wherever it decides the risk warrants the upgrade.

How Do DFARS and CMMC Map to Each Other?

The easiest way to understand the relationship is to see the two frameworks side by side. DFARS created the obligation years ago. CMMC gives that obligation a certification structure and a verification method.

Category DFARS 252.204-7012 CMMC 2.0
What it is Contract clause establishing the cybersecurity obligation Assessment and certification framework that verifies compliance
Underlying standard NIST SP 800-171 (110 controls) Same NIST SP 800-171 controls at Level 2, plus NIST SP 800-172 at Level 3
Verification method Self-attestation Self-assessment (Level 1, some Level 2) or third-party C3PAO assessment (most Level 2, Level 3 via DIBCAC)
Reporting requirement 72-hour cyber incident reporting to DoD Builds on DFARS reporting; adds ongoing SPRS score maintenance
In effect since 2017 Phased rollout beginning November 10, 2025

Contractors sometimes assume that achieving CMMC certification means they can set DFARS 7012 aside or that meeting DFARS 7012 automatically satisfies CMMC, but neither is true. DFARS 7012 remains the governing clause and CMMC is how the DoW confirms a contractor is living up to it.

Where Does the CMMC Rollout Stand Right Now?

CMMC’s path to enforcement ran through two separate rulemaking processes and the distinction matters for anyone trying to track deadlines. The first, known as the 32 CFR Program Rule, established the CMMC program itself. It set the three certification levels, defined the assessment scope and created the role of the C3PAO. That rule was finalized in October 2024 and took effect in December 2024.

The 32 CFR rule alone did not let contracting officers put CMMC language into live solicitations. A second rule under Title 48 of the Code of Federal Regulations updated DFARS clause 252.204-7021 to give contracting officers the authority to require CMMC as a condition of contract award. That rule published in the Federal Register on September 10, 2025 and took effect 60 days later, on November 10, 2025.

As of this writing, CMMC requirements have been appearing in new DoW solicitations for several months under Phase 1 of the rollout. Phase 2, which shifts most Level 2 contractors from self-assessment to mandatory third-party C3PAO certification, begins November 10, 2026. Given that closing the gaps found in a Level 2 assessment typically takes six to twelve months, contractors who have not already run their assessments are running out of runway.

C3PAO capacity is a real constraint, not just a compliance detail. Assessor calendars have filled steadily since Phase 1 began and the closer the industry gets to the Phase 2 deadline, the harder it will be to book an assessment on short notice. A contractor that waits until a specific solicitation requires their certification may find that even a fully compliant environment cannot undergo an assessment in time to bid, which is why mapping out the certification path to a CMMC deadline well in advance matters as much as the technical work itself.

What Happens as CMMC Becomes a Contract Condition?

The DoW designed CMMC’s rollout as a four-phase plan rather than a single hard cutover and each phase changes what contracting officers can require.

  1. Phase 1 (November 10, 2025 to November 9, 2026): New solicitations and contracts may require Level 1 or Level 2 self-assessment. The DoW retains discretion to require full Level 2 C3PAO certification for specific contracts during this phase.
  2. Phase 2 (November 10, 2026 to November 9, 2027): Level 2 C3PAO certification becomes the standard requirement for applicable new contracts. The DoW gains discretion to require Level 3 DIBCAC assessment where warranted.
  3. Phase 3 (November 10, 2027 to November 9, 2028): Level 2 C3PAO certification extends to option period exercises on existing contracts, not just new awards. Level 3 requirements become the standard for applicable solicitations.
  4. Phase 4 (November 10, 2028 forward): Full implementation applies across every applicable DoW solicitation and contract, including option period exercises, with no further phase-in exceptions.

The practical effect is that contractors cannot wait for their specific contract vehicle to force the issue. Once a solicitation includes the CMMC clause, a contractor without the required certification is simply ineligible to compete, regardless of past performance or their relationship with the program office. That is a meaningfully harder line than the self-attestation era, when a contractor could simply sign the DFARS clause and sort out the details later.

What Is the SPRS Score and Why Does It Matter So Much?

What Is the SPRS Score and Why Does It Matter So Much

Alongside DFARS 7012, contractors must post a current NIST SP 800-171 assessment score in the Supplier Performance Risk System (SPRS). That requirement used to live in standalone clauses DFARS 252.204-7019 and 252.204-7020, but a February 2026 regulatory overhaul eliminated 7019 and renumbered 7020 to DFARS 252.240-7997, folding the scoring obligation into DFARS 252.204-7021, the CMMC clause. That score reflects how many of the 110 controls the contractor has in place, out of a maximum possible score of 110.

Contracting officers use the SPRS score during source selection and a stale or inflated score can disqualify a bid before the technical evaluation even begins. Contractors must also refresh the score at least every three years or sooner if their environment changes in a way that affects how they handle CUI, such as bringing on a new system or switching vendors.

Inaccurate SPRS scores create legal exposure, not just a lost bid. When a senior official affirms a score that does not reflect reality, the company has made a false statement to the federal government in connection with a contract. The Department of Justice treats cybersecurity compliance misrepresentations as an enforcement priority under its Civil Cyber-Fraud Initiative and inaccurate affirmations can trigger False Claims Act liability, which carries treble damages and per-claim penalties.

The math behind the score also matters. Each of the 110 controls carries a weighted point value and a fully compliant environment scores 110. Missing or partially implemented controls subtract points, sometimes heavily, which is why organizations that assume they are close to compliant are often surprised by how low an honest self-assessment scores. Running the assessment early, well before a bid deadline, gives compliance teams room to remediate the highest weighted gaps before the score becomes part of a public record tied to an active solicitation.

What Should Contractors Do Right Now?

Contractors handling CUI have a narrow window before Phase 2 makes third-party certification the default requirement on new Level 2 contracts. A practical path to readiness generally includes the following steps.

  1. Assess your environment against NIST SP 800-171: Identify exactly which of the 110 controls are fully implemented, partially implemented or missing across every system that touches CUI.
  2. Remediate the highest priority gaps first: Focus first on access management and multi-factor authentication, plus incident response, since these are the areas C3PAO assessors scrutinize most closely.
  3. Build and maintain a System Security Plan (SSP): The SSP documents how each control is implemented and gives assessors the reference point they need during a C3PAO review.
  4. Maintain a Plan of Action and Milestones (POA&M): Any control that is not yet fully in place needs a documented remediation timeline, since an open-ended gap is treated very differently from one with a clear plan.
  5. Post an accurate, current SPRS score: Refresh the score whenever your environment changes and well before it becomes stale under the three-year rule.
  6. Engage a C3PAO before you need one: Assessor calendars are filling quickly as Phase 2 approaches and waiting until a solicitation requires certification leaves no room for remediation if gaps surface during the assessment.

Organizations that try to manage this internally often discover how demanding it is only after a gap assessment or a failed C3PAO review, at which point catching up costs far more than budgeting for gap assessment, remediation and certification would have cost from the start.

Get Ahead of DFARS and CMMC with Red River

DFARS 252.204-7012 set the bar for protecting CUI years ago and CMMC now gives the DoW a structured way to confirm contractors are clearing it. The two frameworks work together rather than in competition. Treating them as separate obligations only adds confusion to an already complex compliance landscape.

With Phase 2 of the CMMC rollout arriving on November 10, 2026, the contractors who start their gap assessment now are the ones who will still be eligible to bid when the requirement tightens. Waiting until a specific solicitation forces the issue leaves little room to remediate control gaps, build an SSP or book a C3PAO before the deadline that matters lands on your desk.

Red River helps defense contractors and DIB suppliers get ready for CMMC in four ways:

  • Assess your environment against NIST SP 800-171 and close the gaps that matter most.
  • Help you prepare confidently for C3PAO assessment.
  • Scope the CUI boundary across your systems and build and maintain the SSP and POA&M documentation assessors expect to see.
  • Keep your SPRS score current so it reflects your real security posture rather than a best guess from years ago.

For contractors that lack the internal bandwidth to run this as a standing program, Red River can also operate the underlying NIST SP 800-171 controls directly, giving smaller subcontractors the same level of readiness that larger primes build in house.

Contact Red River to schedule a DFARS and CMMC readiness consultation and find out exactly where your organization stands.

Frequently Asked Questions

Does CMMC apply to subcontractors or only prime contractors?

CMMC flows down through the entire supply chain, not just to prime contractors. If a subcontractor handles CUI in any capacity on behalf of a prime, that subcontractor must meet the CMMC level appropriate to the information it handles, regardless of its size or its direct relationship with the DoD. Primes are increasingly requiring proof of certification from their subcontractors well before a contract award, since a subcontractor’s noncompliance can jeopardize the prime’s own eligibility.

What is the difference between FCI and CUI for CMMC purposes?

Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release and it typically triggers Level 1 requirements. Controlled Unclassified Information (CUI) carries a higher sensitivity designation and typically triggers Level 2 requirements. Common examples include technical data and export-controlled information, along with certain personally identifiable information tied to a defense program. Correctly classifying which category your organization handles is one of the first and most consequential steps in scoping a CMMC assessment, since misclassifying CUI as FCI can leave a contractor certified at the wrong level. Contracting officers and program managers can usually confirm how a given contract’s information should be classified and that conversation is worth having well before a self-assessment or C3PAO engagement begins.

Can a company use a cloud environment like Microsoft GCC High to simplify CMMC compliance?

A compliant cloud environment can significantly reduce the scope and cost of a CMMC assessment, since providers like Microsoft GCC High are built around FedRAMP High and DoD-specific compliance frameworks that align closely with NIST SP 800-171. Moving CUI workloads into an environment like GCC High does not eliminate the need for an SSP or a C3PAO assessment and any gaps still belong on a POA&M, but it does shift a meaningful share of the underlying control implementation to the cloud provider.

written by

Corrin Jones

Corrin Jones is the Director of Digital Demand Generation. With over ten years of experience, she specializes in creating content and executing campaigns to drive growth and revenue. Connect with Corrin on LinkedIn.

Go to Top